Privacy Policy

§ 1. Personal data

The cosnova GmbH is delighted that you are interested in our company and our services. It is very important to us that you feel comfortable visiting our website, especially regarding the protection of your personal data. For this reason, we would like to provide you with detailed information about how we handle your personal data. It makes no difference whether you are a visitor of our website or a customer.

The legal requirements for the collection of data on a homepage firstly include a privacy statement that clearly and concisely informs the user about which personal data is stored and for what purposes as well as the ways in which these data are processed and handled.

Personal data are the key to the current data protection legislation. Because whenever data have a personal reference in a legal sense, they may only be collected and processed in accordance with the applicable data protection legislation. In addition to the data protection laws, all other regulations with respect to the handling of personal data must be taken into consideration. Only the collection and processing of personal data for exclusively familial or personal activities remain unaffected by the data protection legislation.

§ 2. The collection of personal data

In the following, you will receive information about which personal data the cosnova GmbH obtains from you. These can be your name, your address as well as information about your end device (e.g. IP address).

§ 2.1. Which data are collected when you visit our website?

When you visit our online service, we shall save for a period of four (4) working days the domain name or the IP address of the requesting computer, the client file request (filename and URL), the http response code, the Internet page from which you are visiting us, as well as the date and the duration of your visit. We save this data to be able to trace any malfunctions or fraudulent use of our online service and our telecommunications services/systems only insofar as necessary to establish further connections and/or for accounting purposes. We do not evaluate your usage data in order to create a personal user profile. In the case of malfunctions or fraudulent use, we reserve the right to report this to the relevant law enforcement authorities. Your usage data is not otherwise used or passed on to third parties.

§ 2.2. Cookies

Cookies are small text files, which store information on the site visitor’s computer. They allow us to recognize and identify visitors to our site. Such cookies are only permitted insofar as they are necessary in order to be able to operate the site (§ 15 Abs. 1 TMG – Article 15, paragraph 1 of the German Telecommunications Act). Other cookies are not permitted (generally also those with a long expiration date).

Please refer to the following overview for information on which cookies are used on our website:

Domain

Cookie Name

Zweck des Cookies

www.catrice.eu

PHPSESSID

Cookie which identifies the server-side user session. The session may contain various information, for example if the user is logged in or not, and the user ID with which the user is logged in. The server session may hold temporarily user input data, for example in case of input forms which are spread over multiple pages.

www.catrice.eu

cookieconsent_dismissed

Cookie that records whether the data protection notice superimposed on the bottom of the page has been confirmed by the user

www.catrice.eu

homeFlowplayerVisitied

Cookie that registers whether the video on the homepage has already been displayed in order to avoid repeated displays of the video in case the user returns to the homepage again during the same session

www.catrice.eu

product_rating_hash

Cookie that is used during the product rating to ensure that each product is only rated once per website visitor session

www.catrice.eu

__olapicU

This cookie is used by the Olapic Component to set an id and anonymize a user to track widget activity for analytics.

PHPSESSID is the cookie photorank.me uses to track a session of a user while using their uploader in the olapic component. Photorank.me needs that session id to be able to identify which is the content the user uploaded in each step of the upload process.

There is the theoretical possibility that further third party services integrated in the site via cross-domain connections might place cookies in the browser for their own domain during a visit to our website without the influence of the CATRICE website. In case the services are also used on other websites, that service can theoretically also read the cookies that it has set on its domain during the visit to the CATRICE website.

Of course, it is also possible to access and surf our website without cookies. You can deactivate the storage of cookies in your respective browser for this purpose. However, please note that this may affect the way in which the website is displayed or limit its functionality. You can also delete cookies at any time. In this case, the contained information will be removed from your end device.

§ 2.3. Social Plugins

It is debatable whether Facebook’s “like” button, Google’s "+1" button and other services of social networks are permissible. The problem is that viewing a page that contains social plugins already provides the operator of the social plugins with the IP address of the site visitor (and probably other data) – without the site visitor noticing or being aware of it.

§ 2.4. Reach analysis

Google Analytics is the most commonly used web analytics service. The operator of the site integrates a code snippet into the source code of its websites, which transfers the site visitor’s data to Google Analytics, where they are evaluated. However, Google also uses these data for other purposes of their own – in particular, for advertising purposes. Since the agreement between the Hamburg Commissioner for Data Protection and Google in September 2011, it is permissible to implement Google Analytics in a legally compliant manner.

For this purpose, cosnova GmbH has:

• entered into a data processing agreement with Google. • shortened your IP address before the data collection by Google.

§ 2.4.1. Privacy policy for the use of Google Analytics

Some of the websites of CATRICE use Google Analytics, a web analysis service of Google Inc. ("Google"). Google Analytics uses what are known as "Cookies", text files that are stored on your computer and which allow an analysis of your use of the website. The information generated by the cookie about your use of this website will generally be transferred to a Google server in the USA and stored there. However, if IP anonymisation is activated on this website, your IP address will be shortened beforehand by Google within Member States of the European Union or in other States party to the Agreement on the European Economic Area. Only in exceptional cases will the full IP address be transferred to a Google server in the USA and shortened there.

Google will use this information on behalf of the operator of this website to evaluate your use of the website, to compile reports on website activities and to provide in respect of the website owner further services associated with site usage and Internet usage. The IP address reported by your browser as part of Google Analytics will not be combined with other data by Google.

You can prevent the storage of cookies by selecting the appropriate settings in your browser software. However, please note that if you do this you may not be able to use the full functionality of this website. You can also prevent the collection of data generated by the cookie and relating to your use of the website (including your IP address) at Google and the processing of this data by Google by downloading and installing the browser add-on available at the following link:

§ 3. Processing and utilisation of personal data

As a general rule, no personal data are collected, processed and/or used solely as a result of your visiting the Catrice website.

If you are asked to provide your name, e-mail address or any other personal information for special offers (e.g., when participating in a survey or a prize draw as well as when subscribing to a newsletter), we will inform you about the collection, processing and use of such data accordingly and request your prior consent. Insofar as personal data is collected, processed and used, cosnova will adhere to the applicable data protection regulations. In particular, the data will be treated confidentially. Personal data will not be disclosed to third parties without your consent unless we are required to do so by law on the basis of a court order or an official decree.

The following is an overview of all cases in which we must collect, process and use your personal data:

Prize draws: Should you decide to participate in one of our prize draws, we will ask you to provide (1) your name as well as (2) your date of birth, (3) your e-mail address and (4) your postal address. We do this so that we are able to inform you in case you win the contest and also in order to ensure that each participant only enters the prize draw once. Attempts to manipulate prize draws by entering or voting multiple times may lead to elimination from the contest or blocking of the IP address to prevent access to the Catrice website.

Newsletter: If you subscribe to our newsletter mailing list, we will ask you to provide your e-mail address. The desired newsletter will then be sent to this e-mail address regularly. Please refer to the Terms of Use for the newsletter for more information on the use of the newsletter, including the cancellation options and deletion of your personal data.

§ 4. Technical and organisational measures

The cosnova GmbH shall take all necessary technical and organisational safety measures to protect your personal data from loss, unauthorised access or other abuse. Thus, your data is saved in a secure operational environment, which cannot be accessed by the public. In certain cases (e.g. processing login data), your personal data is encrypted during transmission. This means that the communication between your computer and our servers is carried out under utilisation of an approved encryption procedure, if your browser supports this.

Our employees are trained in issues pertaining to the Data Protection Act and handle your data and information to which they have access responsibly at all times.

If you wish to contact us via email, we must point out that the confidentiality of the transmitted information is not ensured. The content of emails may be viewed by third parties.

§ 5. Rights of the person affected

You are entitled to request information from us regarding the storage of data relating to your person at all times. In case of incorrect data, you can demand the rectification of these data. Furthermore, you have the right of data portability of your personal data in a commonly used and machine-readable format. You also have the right to restrict the processing of their personal data.

In compliance with the statutory data protection regulations, we shall delete any personal data stored by us without any action on your part if the storage of data is no longer necessary for the fulfilment of the purpose for the which they were originally stored or if the storage is inadmissible for other legal reasons. In certain cases specified by the law (e.g. in case of statutory retention periods), your data may only be blocked instead of deleted.

You also have the right of appeal before the relevant regulatory authorities.

§ 6. The data protection officer

The cosnova GmbH has appointed an external data protection officer to implement the legally required organisational and supervisory tasks. The appointed data protection officer can be reached as follows:

Upon prior arrangement, cosnova GmbH will provide the data protection officer of its clients with access to its data processing systems and enable them to determine the compliance with the applicable data protection regulations.